Software Passport · public repository

estafette/estafette-vulnerability-scanner

Observed by SPR on 2026-09-18 at commit 04d8cc2942d06e37329a8f7b6ebb75bbbbdbbcd3 (main). Source: github.com/estafette/estafette-vulnerability-scanner.

SBOM components9
Open findings9
Critical / high0 / 0
Evidence items13

What was observed

Syft generated the software bill of materials from the repository's manifests; each component was checked against the OSV vulnerability database; the tree was scanned for secrets, infrastructure-as-code issues and licence signals. Vendor-supplied attestations: none — this page contains only independent observation.

Open findings

SeverityFindingComponentFixed in
MEDIUMLicense not observedk8s.io/client-go
MEDIUMLicense not observedk8s.io/apimachinery
MEDIUMLicense not observedk8s.io/api
MEDIUMLicense not observedgopkg.in/yaml.v3
MEDIUMLicense not observedgithub.com/stretchr/testify
MEDIUMLicense not observedgithub.com/rs/zerolog
MEDIUMLicense not observedgithub.com/prometheus/client_golang
MEDIUMLicense not observedgithub.com/estafette/estafette-foundation
MEDIUMLicense not observedgithub.com/alecthomas/kingpin

Get the full passport

Continuous verification, evidence ledger, plain-English and auditor reports, and a shareable signed passport are available to SPR customers.

See plans   Review your own repository free

Software Passport Registry Ltd. Every number on this page was observed by SPR's own scan of the public repository at the commit shown; nothing is estimated or vendor-supplied. Absence of a finding is not proof of safety. Terms · Privacy